MEDIUM
Vanilla before 2.6.1 allows SQL injection via an invitationID array to /profile/deleteInvitation, related to applications/dashboard/models/class.invitationmodel.php and applications/dashboard/controllers/class.profilecontroller.php
Published Sep 3, 2018
6.5
MEDIUMCVSS 3.0
EPSS 0.94%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.